LINUXOR.SK ... open source notes ...

Balabit - CSR template from the CA administrator

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Certificates and keys

noteDo not copy rsa_keygen_pubexp:3. A public exponent of 3 was legal but was already discouraged in 2018; 65537, the default of OpenSSL, is the usual choice (general knowledge, not from my documents). <COUNTRY> and <PUT HERE YOUR FQDN> are placeholders, and "Example Org" stands for the organisation.

The recipe for a certificate request that the CA administrator of the organisation sent: two OpenSSL commands and the answers to give, as comment lines. The example was made out for another server of the management LAN, dc1-a-vcelk001.adm.example.net, and leaves the common name to the requester.

ItemValue
Fromthe CA administrator of the organisation's CA
Written forroot on the server that requests the certificate
KeyRSA 4096, public exponent 3, written unencrypted as a PEM file
Configurationthe default openssl.cnf, so no alternative names are requested
Subject asked forcountry, locality Site 1, organisation Example Org, the server's FQDN, e-mail admin02@example.net; no state, no organisational unit
Used for the SCBnot directly: the IPMI requests whose certificates are dated January 2018 give the same answers, with genrsa and 2048-bit keys
Sourcethe end of my working notes, section "CERTIFICATE request - from the CA administrator"

The commands

The two commands of the template, to run as root on the requesting server.

bash
$ openssl genpkey -algorithm RSA -out dc1-a-vcelk001.adm.example.net.pem -pkeyopt rsa_keygen_bits:4096 -pkeyopt rsa_keygen_pubexp:3
$ openssl req -new -key dc1-a-vcelk001.adm.example.net.pem -out dc1-a-vcelk001.adm.example.net.csr

The answers, as the template gives them.

output 10 lines
# Answers
#Country Name (2 letter code) [XX]:<COUNTRY>
#State or Province Name (full name) []:
#Locality Name (eg, city) [Default City]: Site 1
#Organization Name (eg, company) [Default Company Ltd]: Example Org
#Organizational Unit Name (eg, section) []:
#Common Name (eg, your name or your server's hostname) []: <PUT HERE YOUR FQDN>
#Email Address []: admin02@example.net
#A challenge password []:
#An optional company name []:
LineWhat it means
genpkey -algorithm RSA … -pkeyopt rsa_keygen_bits:4096the general key command of OpenSSL; genrsa, which my own rounds used, makes the same kind of RSA key (general OpenSSL knowledge)
-pkeyopt rsa_keygen_pubexp:3the public exponent; see the note above
#State or Province Name (full name) []:left empty, as the CA's subjects have no state
#Email Address []: admin02@example.netthe template already carries admin02's address, the same one as in all my requests

Checked against OpenSSL 3.5

As builtToday
-pkeyopt rsa_keygen_pubexp:3the default exponent is 65537; OpenSSL documents 3 as accepted "for legacy reasons" and deprecated
genpkey -algorithm RSA … rsa_keygen_bits:4096unchanged

Dropping the rsa_keygen_pubexp option is all the template needs.

← solutionz